New Cyberthreat 'Boolka' Deploying BMANAGER Trojan via SQLi Attacks
ID: 27e999c0-5c77-5aaa-9bca-a099a350bf31
STIX ID: report--27e999c0-5c77-5aaa-9bca-a099a350bf31
Feed Name: The Hacker News
**Boolka** is an opportunistic criminal actor that has been exploiting SQL injection vulnerabilities since at least 2022 to inject malicious JavaScript into websites which exfiltrates user inputs and redirects victims to a fake loader that delivers a downloader for the modular trojan **BMANAGER**; BMANAGER deploys modules (BMBACKUP, BMHOOK, BMLOG, BMREADER) to harvest files, record focused applications and keystrokes, export stolen data, and maintain persistence (noted indicators include the C2 domain boolka.tk and a hard-coded local DB path C:\Users\{user}\AppData\Local\Temp\coollog.db).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
